AI Regulation Tracker · EU AI Act · Guidance

What does Commission guidelines on the AI system definition say about AI in banking?

Published Feb 6, 2025 · Last reviewed Oct 5, 2026

The European Commission published its Guidelines on the definition of an artificial intelligence system on 6 February 2025, four days after the definition and the Article 5 prohibitions began to apply on 2 February 2025; the language versions were formally adopted on 29 July 2025 as C(2025) 5053. The Guidelines are non-binding and break the Article 3(1) definition into seven elements: a machine-based system, designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, for explicit or implicit objectives, infers from input how to generate outputs, such as predictions, content, recommendations or decisions, that can influence physical or virtual environments. They say that systems for 'mathematical optimisation' based on well-established methods such as linear or logistic regression fall outside the definition, and that rule-based or basic data-processing software does too, while machine-learning systems such as fraud detection trained on labelled transaction data are examples of AI systems. For a bank this is the first scoping question: a model is only subject to the AI Act's high-risk or transparency rules if it first qualifies as an AI system.

OFFICIAL TEXT: digital-strategy.ec.europa.eu ↗ · IN FORCE · EU AI ACT

DocumentCommission guidelines on the AI system definition — Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act)
Issued byRegulation (EU) 2024/1689 — the EU Artificial Intelligence Act
TypeGuidance
StatusIn force
PublishedFeb 6, 2025
Applies toProviders, deployers and other actors assessing whether a software system is an 'AI system' under Article 3(1) of the AI Act; for banks, the test that decides whether a credit, fraud, AML or chatbot tool is in scope of the Act at all. Non-binding; only the Court of Justice can interpret the Act authoritatively
Official sourcedigital-strategy.ec.europa.eu ↗
Use casesCredit scoring & underwriting · Model risk management · Fraud detection · AI governance (general) · Generative & agentic AI

What are the key points of Commission guidelines on the AI system definition?

  • Status and date: published 6 February 2025 as the approved draft Communication C(2025) 924; the formally adopted Communication is C(2025) 5053 of 29 July 2025. Paragraph 7: the Guidelines are not binding and only the CJEU can give an authoritative interpretation.
  • Seven elements of the Article 3(1) definition (paragraph 9): machine-based system; varying levels of autonomy; possible adaptiveness after deployment; explicit or implicit objectives; inference of how to generate outputs; outputs such as predictions, content, recommendations or decisions; influence on physical or virtual environments.
  • Inference is the key criterion (paragraphs 26-45): it covers machine-learning approaches (supervised, unsupervised, self-supervised, reinforcement and deep learning) and logic- and knowledge-based approaches; the Guidelines name fraud detection systems trained on labelled transaction data as a supervised-learning example (paragraph 34).
  • Excluded by the Commission's reading (paragraphs 41-51): systems for improving mathematical optimisation, including 'linear or logistic regression methods' that do not 'transcend basic data processing' (paragraph 42); basic data processing following fixed human-programmed rules (paragraph 46); classical heuristics; and simple prediction systems based on basic statistical rules such as a historical average (paragraphs 49-51).
  • Autonomy (paragraphs 14-21): a system with some degree of independence of action from human involvement is autonomous; a system that needs full manual involvement or is exactly specified by a human does not meet the element.
  • Paragraph 61-62: the assessment must follow the specific architecture and functionality of each system; no automatic determination or exhaustive list of in-scope or out-of-scope systems is possible.
  • Paragraph 63: only certain AI systems face regulatory obligations; the vast majority, even if they qualify as AI systems, are not subject to any requirement of the AI Act, which reaches prohibited practices (Article 5), high-risk systems (Article 6) and the transparency duties of Article 50.
  • The Guidelines were adopted in parallel with the Commission's guidelines on prohibited AI practices, and the definition applied from 2 February 2025 together with Chapters I and II of the Act (paragraph 4).

What did Commission guidelines on the AI system definition change for banks?

The Act's definition is broad and deliberately technology-neutral, and banks had no way to tell whether long-established scorecards and statistical models counted. The Guidelines give a partial answer: well-established regression-based optimisation and fixed-rule software sit outside the definition, while machine-learning models that infer from data are inside it. That matters most for Annex III credit-scoring and creditworthiness systems, where being inside or outside the definition decides whether the high-risk regime applies, and the EIOPA opinion on AI governance applies the same definition and paragraph 42 for insurers.

How do the Commission guidelines define an AI system, and which bank models fall outside it?

The Commission's Guidelines on the definition of an AI system, published on 6 February 2025 and adopted as C(2025) 5053 on 29 July 2025, read Article 3(1) of the AI Act as seven elements, of which inference — generating predictions, content, recommendations or decisions from input — is the one that separates AI from ordinary software. They exclude systems built on well-established optimisation methods such as linear or logistic regression that do not go beyond basic data processing, fixed-rule software and simple statistical predictors, but they say that no list is exhaustive and each system must be assessed individually. For a bank, a machine-learning credit, fraud or chatbot system is presumptively an AI system; a legacy rule-based scorecard may not be, but the conclusion has to be documented.

RuleAuthorityWhat it requiresApplies
Paragraph 9 — Seven elements of the definitionEU AI ActTest each system against all seven elements of Article 3(1): machine-based, autonomy, adaptiveness, objectives, inference, outputs, influence on environments.Definition applies since 2 Feb 2025
Paragraphs 26-45 — Inference and AI techniquesEU AI ActTreat machine-learning methods (supervised, unsupervised, reinforcement, deep learning) and logic- and knowledge-based approaches as capable of inference; fraud detection trained on labelled transaction data is a named example.Guidance since 6 Feb 2025
Paragraph 42 — Optimisation and regression methodsEU AI ActSystems that accelerate or approximate traditional, well-established optimisation methods such as linear or logistic regression fall outside the definition where they do not transcend basic data processing.Guidance since 6 Feb 2025
Paragraph 46 — Basic data processingEU AI ActSoftware executing fixed human-programmed rules, such as database sorting or spreadsheets without AI features, is not an AI system.Guidance since 6 Feb 2025
Paragraphs 61-62 — Case-by-case assessmentEU AI ActDecide on the system's specific architecture and functionality; no automatic determination or exhaustive list of in-scope systems exists.Guidance since 6 Feb 2025
Paragraph 63 — Risk-based reach of the ActEU AI ActOnly prohibited practices (Article 5), high-risk systems (Article 6) and listed transparency cases (Article 50) carry obligations; most AI systems carry none under the Act.Prohibitions since 2 Feb 2025; high-risk Annex III from 2 Dec 2027

The Guidelines sit beneath the AI Act itself (Regulation (EU) 2024/1689) and were adopted in parallel with the Commission's guidelines on prohibited practices. They do not create obligations; they show how the Commission and the national market surveillance authorities are likely to read the definition, and the EIOPA opinion on AI governance explicitly relies on them and quotes paragraph 42.

The practical edge for banks is the boundary around statistical models. Credit scorecards built on logistic regression are the classic example: the Commission's text puts well-established regression-based optimisation outside the definition, but it also stresses the system-by-system test. A scorecard that is retrained automatically, uses unstructured data, or is combined with a machine-learning component is a different case from a static, long-used model.

Being in scope of the definition is distinct from being high-risk. Whether a system is in Annex III depends on its use, and the deadline for standalone Annex III systems was moved to 2 December 2027 by Regulation (EU) 2026/1744.

WHAT THIS MEANS IN PRACTICE

  • Run the seven-element test as a documented step in the model inventory for every model used in credit, fraud, AML, pricing and customer service, and record the outcome and reasoning.
  • Where a model is classed as out of scope on the basis of paragraph 42 or 46, keep evidence that it has no self-learning, adaptive or non-rule-based component and has been used in a consolidated manner.
  • Treat vendor models by the same test; ask vendors to state whether their product is an AI system within Article 3(1).
  • Reassess when a model is retrained on new data, replaced, or combined with machine-learning components, since the classification can change.
  • Remember that out-of-scope models still fall under model risk rules such as SR 11-7 and PRA SS1/23 and, in the EU, the CRR and EBA guidelines.

Is logistic regression an AI system under the EU AI Act?

The Commission's Guidelines say that systems used to improve mathematical optimisation or to approximate traditional, well-established optimisation methods, such as linear or logistic regression, fall outside the definition because they do not transcend 'basic data processing' (paragraph 42). That is not a blanket exemption for every statistical scorecard; the Guidelines say each system must be assessed on its own architecture and functionality, so a bank should document the reasoning for each credit model it treats as out of scope.

Are the Commission's AI system definition guidelines binding?

No. Paragraph 7 states that the Guidelines are not binding and that any authoritative interpretation of the AI Act may ultimately only be given by the Court of Justice of the European Union. In practice, market surveillance authorities and the AI Office are expected to follow them.

When did the AI system definition start to apply?

The definition in Article 3(1) of the AI Act has applied since 2 February 2025, together with the Chapter I and II provisions including the Article 5 prohibitions. The Guidelines were published on 6 February 2025 and formally adopted as C(2025) 5053 on 29 July 2025.

Does the AI Act definition cover rule-based fraud or AML systems at banks?

Systems that follow predefined, explicit rules without learning, reasoning or modelling are 'basic data processing' and fall outside the definition (paragraph 46). A fraud or AML tool that learns patterns from labelled or unlabelled data is an AI system; the Guidelines cite fraud detection trained on labelled transaction data as an example.

Does being an AI system mean a bank's model is high-risk?

No. Qualifying as an AI system is only the first step. Paragraph 63 says that most AI systems face no AI Act requirements; high-risk status depends on Article 6 and Annex III, which lists creditworthiness assessment and credit scoring of natural persons, and the Digital Omnibus moved those high-risk obligations to 2 December 2027.

DateDocumentStatus
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force
Jul 20, 2026Commission guidelines on AI Act Article 50 transparency — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act)In force
May 19, 2026Draft Commission guidelines on high-risk classification — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI ActProposed
Nov 21, 2025EBA factsheet on the AI Act — AI Act: implications for the EU banking and payments sector (EBA factsheet)Final
Jul 18, 2025Commission GPAI model guidelines — Commission Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act)In force
Jul 10, 2025General-Purpose AI Code of Practice — General-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters)In force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning